CVE-2007-5849
CUPS <1.3.4 - RCE
Title source: llmDescription
Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.
Exploits (1)
References (26)
Scores
EPSS
0.3458
EPSS Percentile
97.0%
Details
CWE
CWE-189
Status
published
Products (5)
easy_software_products/cups
1.2.4
easy_software_products/cups
1.2.9
easy_software_products/cups
1.2.10
easy_software_products/cups
1.2.12
easy_software_products/cups
1.3.3
Published
Dec 19, 2007
Tracked Since
Feb 18, 2026